>>189193,
>>189194,
>>189195,
>>189196,
>>189197,
>>189198,
>>189199,
>>189200,
>>189201,
>>189202,
>>189203,
>>189204,
>>189205,
>>189206,
>>189207,
>>189208,
>>189209,
>>189210,
>>189211,
>>189212,
>>189213DNI Pulte @DNIPulte - Redacted Document: NIC NATIONAL INTELLIGENCE COUNCIL
NIC
audits (now required in 38 states), which can alert election officials to manipulation or errors.
We assess that cyber operations targeting the electronic tabulation of results could delay results reporting from affected jurisdictions, potentially creating public uncertainty but probably not affecting the integrity of certified results. Tabulated results are stored independently of copies displayed on results websites, although investigations of malicious activity could delay results and introduce public uncertainty about the validity of vote counts. Denial of service (DOS) attacks or manipulation of copies of the results in transit would delay public access to the results or make them difficult to access, creating the appearance of modified results.
The Blue Ribbon Commission on the vulnerabilities of Pennsylvania's election infrastructure found the transmission of preliminary results to public-facing websites is vulnerable to "man-in-the-middle" attacks, in which the attacker manipulates data mid- transmission. Such attacks would not alter separately stored certified copies of tabulation results, which are processed offline, but even short delays in reporting the results could introduce doubts about the security of the election or the validity of the results.
In May 2019, unidentified cyber actors rendered a US county election website unavailable on the night of a mayoral primary; the incident did not affect the tabulation results, which were stored on a separate system not connected to the Internet.
NATIONAL INTELLIGENCE COUNCIL
False Manipulation Narratives Could Undermine Public Confidence
We assess that adversaries could also make false claims about their ability to manipulate US election infrastructure as part of a broader effort to undermine confidence in US democratic processes. Much of the voting public probably knows little about the process of administering US elections, which could allow false narratives to gain traction. Government efforts to investigate and publicly invalidate such claims could take weeks or months, providing time for concerns about election security to spread. Disproving claims would also be impossible if adversaries evaded US intelligence collection.
Adversaries could make wholly fabricated claims, such as announcing that they have compromised all US voting machines, a claim that would be difficult and time-consuming-or impossible for the US Government to disprove.
Adversaries could also link an exaggerated claim-for example, about their ability to affect the election outcome to actual operations, such as DOS attacks against election-related websites or intrusions into voter registration databases. Linking the two could introduce public doubts about the validity of the election, even if the actual cyber operations were unrelated to the casting, tabulating, and reporting of votes.
A widely publicized compromise of election infrastructure probably would undercut public confidence in the election, even if the compromise was not used to manipulate election- related data or systems.
Mitigating Threats to Infrastructure
We assess that enhancing the physical security and cyber protections of election systems and messaging the US public and adversaries could mitigate some of the vulnerabilities of the complex US election process. Potential measures include the following:
[4]
https://x.com/DNIPulte/status/2082073836040667541
Message too long. Click here to view full text.